Documentation
Artifact types
Every artifact in the registry has a specific Gemara type. Here's what each one is, in the Gemara model's own terms — and where to browse it.
Most artifact types in the registry are catalogs — per Gemara, a structured set
of related prose and relevant metadata
— each collecting one kind of Gemara concept. The
definitions below are quoted from the Gemara lexicon — follow the links for the full schema.
Control Catalogs
A Control is a mechanism, such as a safeguard or countermeasure, that asserts
desired state
(Layer 2) — the prescriptive objectives a system should meet.
Browse controls →
Threat Catalogs
A Threat is a circumstance or event where the concepts of a vector are applied to
a Capability in a specific context, resulting in the potential for negative impact
(Layer 2).
Browse threats →
Capability Catalogs
A Capability is a feature or function of a system; the primary component
comprising an attack surface
(Layer 2). Browse capabilities →
Guidance Catalogs
Guidance is prose intended to help bring about a desired outcome for a topic or
generalized scenario, based on knowledge of relevant Vectors
(Layer 1).
Browse guidance →
Vector Catalogs
A Vector is an opportunity for an attacker to exploit a vulnerability in the
system
— or a path by which neglect could cause unintentional harm (Layer 1).
Browse vectors →
Principle Catalogs
Principle Catalogs collect cross-cutting principles that motivate guidance and controls. Gemara's
lexicon doesn't yet define "Principle" as a distinct term, so these are catalogs in the general sense
— a structured set of related prose and relevant metadata.
Browse principles →
Evaluators
Not a catalog: an evaluator is an executable Privateer plugin that produces evaluation evidence (Layer 5). See Evaluators.
📖 Full schemas and definitions for every type: gemara.openssf.org.